º£½ÇºÚÁÏ

Journalism from the º£½ÇºÚÁÏ
Context is no longer producing new reporting, but this site will remain as an archive.

India health data faces rising risk of breaches, cyberattacks

A healthcare worker gives a dose of vaccine against the coronavirus disease (COVID-19) to a worker at salt pan in Surendranagar district in the western state of Gujarat, India, February 18, 2022

A healthcare worker gives a dose of vaccine against the coronavirus disease (COVID-19) to a worker at salt pan in Surendranagar district in the western state of Gujarat, India, February 18, 2022. REUTERS/Amit Dave

What’s the context?

The recent leak of vaccination data of millions of Indians shows the risk of digitising health data without adequate protections

  • Leak of vaccination data of millions of Indians concerning, say digital experts
  • Push to digitise health data without safety measures "reckless"
  • Authorities say data is secure, plan to introduce data protection law

Last year, responding to reports of breaches of data from India's CoWIN vaccine portal, the head of the National Health Authority, RS Sharma, said that it had " and has never faced a security breach."

Last month, Sharma's own personal data was via the Telegram app. Officials first denied a breach had taken place, then days later, Delhi police said they had in relation to the leak.

The data leak - including names, Aadhaar national IDs, mobile numbers, voter IDs, passports and COVID vaccination status of millions of individuals - was one of the largest in India, and came on the heels of other breaches of CoWIN and Aadhaar data, and the records of a leading hospital in Delhi.

A man speaks on his mobile phone while sitting atop sacks of consumer goods inside a delivery truck with JioMart's supplies for retailers in a crowded market in Sangli, in the western state of Maharashtra, India, October 22, 2021 REUTERS/Abhirup Roy
Go DeeperIndia push for digital sovereignty risks more online surveillance
A silhouette is surrounded by security cameras in this illustration. º£½ÇºÚÁÏ/Nura Ali
Go DeeperSurveillance nation: India spies on world's largest population
A CCTV camera, installed on the boundary wall of a house is pictured at Vaikom in the Kottayam district of the southern state of Kerala, India November 23, 2017
Go DeeperIn India's surveillance hotspot, facial recognition taken to court

The recent breaches of health data are particularly concerning, digital experts said, as they leave individuals vulnerable to scams, harassment and discrimination without remedy in the absence of a data protection law in the country.

They warned it also undermines India's aim to develop and export to Asian and African countries its digital public infrastructure model comprising Aadhaar, mobile payment system UPI and the National Health Stack data platform, that authorities say will improve access and efficiency.

But in pushing its digital public infrastructure "India is putting people at risk from data collection and data overreach," said Raman Jit Singh Chima, Asia policy director at digital rights group Access Now. "It's a bad model."

"The push for greater digitisation of health data is happening without discussion or adequate data protection. India is seeing an increase in cyberattacks, and the refusal to acknowledge breaches and to hold institutions accountable is a reckless approach," he said.

The ministry of electronics and information technology did not respond to a request for comment.

The health ministry, in a June 12 statement, said that the CoWIN portal "is completely safe with . All steps have been taken and are being taken to ensure security of the data."

A healthcare worker enters data into the COVID Vaccine Intelligence Network (CoWIN) app, a digital platform being used for vaccine distribution, during a trial run of COVID-19 vaccine delivery systems, at a village near in Gandhinagar, India, December 29, 2020

A healthcare worker enters data into the COVID Vaccine Intelligence Network (CoWIN) app, a digital platform being used for vaccine distribution, during a trial run of COVID-19 vaccine delivery systems, at a village near in Gandhinagar, India, December 29, 2020. REUTERS/Amit Dave

  • 1
  • 2

The federal Computer Emergency Response Team was investigating the incident, it added. No details have since been released.

Junior IT minister Rajeev Chandrasekhar said at the time that the leaked CoWIN data was accessed by a bot "from a threat actor database, which seems to have been populated with previously breached/stolen data."

"It does not appear that CoWIN app or database has been directly breached," he said on Twitter.

Highly sensitive

Under the ambitious Digital India programme, there is increasing digitisation of data and services in the country.

The national digital health mission that aims to link individual health records to a unique ID similar to the Aadhaar ID, has raised concerns about data security and the potential for misuse.

In the rush to build out the digital public infrastructure, "the very suitability of these technologies has gone unchallenged," said Aarushi Gupta at Digital Futures Lab, a research collective.

"Given the vast amounts of data collection, processing, and exchange ... citizens are at considerable risk of their data being leaked and their privacy rights being compromised, as seen with the recent leak," she added.

India was the biggest target for cyberattacks after the United States in 2021 and 2022, with , an increase of nearly a fourth, according to cybersecurity firm CloudSEK.

A separate study by NordVPN, a virtual private network service provider, last year showed India was the worst hit by data breaches, with some and sold on bot markets by hackers.

Biggest data hacks and cyberattacks in India. Graph

Biggest data hacks and cyberattacks in India. Graph, Bhasker Tripathi/º£½ÇºÚÁÏ

Biggest data hacks and cyberattacks in India. Graph, Bhasker Tripathi/º£½ÇºÚÁÏ

Last year, India took aim at , with new legislation that it said would improve cybersecurity, including requiring firms to report data breaches within six hours of noticing them.

But India's national cybersecurity policy hasn't been updated since 2013, leaving the country's expanding digital infrastructure vulnerable to new threats, said Prateek Waghre, policy director at Internet Freedom Foundation, a non-profit.

It is also not clear if a long-delayed data protection bill that is expected to be passed soon, will protect sensitive health data, he told Context.

"There is a question of how effective the bill will be, and whether government agencies will be exempt from accountability in case of a breach," Waghre added.

"The more data there is, the more it can be abused. If you can access the entire medical history of individuals, imagine how valuable that is for the private sector; how will it be protected from misuse?"

Major target

of hacks and cyberattacks, with vaccination records and the personal information of patients and healthcare workers most frequently targeted, according to a study by CloudSEK.

In November, the All India Institute of Medical Sciences (AIIMS), a federal government hospital that caters to ministers, politicians and the general public, was that shut down its servers and disrupted patient care for weeks.

The attack, which officials said had , is reported to have compromised the records of up to 40 million patients.

Earlier, the was exposed online by a government agency, local media reported.

"Any data leak is harmful, and there are no protocols for confidentiality of sensitive data such as pregnancy, HIV treatment or vaccinations," said Amulya Nidhi, founder of Jan Swasthya Abhiyan, or People's Health Movement, a non-profit.

"With leaks of such sensitive data, people can be badly affected. Our entire social framework can be affected."

(Reporting by Rina Chandran in Bangkok. Editing by Zoe Tabary)


Context is powered by the º£½ÇºÚÁÏ Newsroom.

Our Standards:


Tags

  • Tech and inequality
  • Tech regulation
  • Data rights
  • Cyberspace

Featured

It's no secret that AI needs a lot of water and energy. But how much exactly is difficult to verify. We went on the ground to find out.



The Backstory

New Tab IconThese links open on



Dataveillance: Your monthly newsletter for a watched world.

By providing your email, you agree to our Privacy Policy.


Latest on Context

Footer, º£½ÇºÚÁÏ Logo

Context is a media platform created by the º£½ÇºÚÁÏ. We provide news and analysis that contextualises how critical issues and events affect ordinary people, society and the environment. Find out more.

Our Products
  • Workforce Disclosure Initiative

    The Workforce Disclosure Initiative is an investor-backed project to improve the quantity & quality of corporate workforce data, via an annual survey & engagement process.

  • Trust Conference

    Trust Conference is the º£½ÇºÚÁÏ’s flagship annual event, taking place in the heart of London each year.

  • TrustLaw

    TrustLaw is the º£½ÇºÚÁÏ’s global pro bono service, facilitating free legal assistance to NGOs and social enterprises around the world.